Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8xx-8vm8-x6wj

Опубликовано: 18 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Resque vulnerable to Reflected Cross Site Scripting through pathnames

Impact

resque-web in resque versions before 2.1.0 is vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint.

Patches

v2.1.0

Workarounds

No known workarounds at this time. It is recommended to not click on 3rd party or untrusted links to the resque-web interface until you have patched your application.

References

https://github.com/resque/resque/issues/1679 https://github.com/resque/resque/pull/1687

Пакеты

Наименование

resque

rubygems
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 76%
0.00943
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-233
CWE-79

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 лет назад

Resque (pronounced like "rescue") is a Redis-backed library for creating background jobs, placing those jobs on multiple queues, and processing them later. resque-web in resque versions before 2.1.0 are vulnerable to reflected XSS through the current_queue parameter in the path of the queues endpoint. This issue has been patched in version 2.1.0.

EPSS

Процентиль: 76%
0.00943
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-233
CWE-79